Latest CVE Feed
-
9.3
HIGHCVE-2010-5189
Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote authenticated users to execute arbitrary CLI commands by leveraging read-only administrator privileges and establishing an H... Read more
Affected Products : sgos proxysg proxysg_sg210-10 proxysg_sg210-25 proxysg_sg210-5 proxysg_sg510-10 proxysg_sg510-20 proxysg_sg510-25 proxysg_sg510-5 proxysg_sg810-10 +6 more products- EPSS Score: %0.57
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-5006
Heap-based buffer overflow in npdjvu.dll in Caminova DjVu Browser Plug-in 6.1.4 Build 27351 and other versions before 6.1.4.27993 allows remote attackers to execute arbitrary code via a crafted Sjbz chunk in a djvu file.... Read more
Affected Products : djvu_browser_plug-in- EPSS Score: %7.85
- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-6422
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memor... Read more
- EPSS Score: %6.61
- Published: Dec. 18, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-6271
Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitrary signed Xtras via a Shockwave movie that contains an Xtra URL, as demonstrated by a URL for an outdated Xtra.... Read more
Affected Products : shockwave_player- EPSS Score: %0.59
- Published: Dec. 20, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-5937
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execut... Read more
Affected Products : sterling_b2b_integrator sterling_file_gateway gentran_integration_suite sterling_integrator- EPSS Score: %1.49
- Published: Apr. 12, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0685
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which allows remote attackers to execute arbitrary code or cause a denial of service (resource consumption) via unk... Read more
Affected Products : wonderware_information_server- EPSS Score: %2.48
- Published: May. 09, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-1115
Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a cra... Read more
Affected Products : webex_advanced_recording_format_player- EPSS Score: %1.51
- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-5369
IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code by deploying and accessing a service.... Read more
Affected Products : spss_analytical_decision_management- EPSS Score: %8.92
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-5990
Unspecified vulnerability in JustSystems Ichitaro 2006 through 2011; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen and Gen Trial Edition; Ichitaro Pro; Ichitaro Pro 2 and Pro 2 Trial Edition; Ich... Read more
- EPSS Score: %5.13
- Published: Nov. 13, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-6874
Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file.... Read more
Affected Products : light_alloy- EPSS Score: %35.15
- Published: Nov. 26, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-3482
Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in an ERS f... Read more
Affected Products : erdas_er_viewer- EPSS Score: %65.74
- Published: Jan. 19, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-4979
Buffer overflow in the gldll32.dll module in EPS Viewer 3.2 and earlier allows remote attackers to execute arbitrary code via a crafted EPS file.... Read more
Affected Products : eps_viewer- EPSS Score: %11.71
- Published: Jan. 31, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-6949
The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device.... Read more
Affected Products : wemo_home_automation_firmware- EPSS Score: %0.62
- Published: Feb. 22, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2014-2087
Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code v... Read more
Affected Products : free_download_manager- EPSS Score: %46.39
- Published: Mar. 18, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2013-0733
Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jp... Read more
- EPSS Score: %7.88
- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-3911
Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeControlLocalName, (3) DeleteDeviceProfile, (4) FrameAdvanceReader, or other unknown method in the XNSSDKDEVICE.X... Read more
Affected Products : ipolis_device_manager- EPSS Score: %11.41
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-7178
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.... Read more
Affected Products : tuleap- EPSS Score: %10.01
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-6119
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to execute arbitrary code via a crafte... Read more
- EPSS Score: %9.94
- Published: Dec. 23, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2011-5295
Buffer overflow in the Download method in a certain ActiveX control in MDIEEx.dll in Gogago YouTube Video Converter 1.1.6 allows remote attackers to execute arbitrary code via a long argument.... Read more
Affected Products : gogago_youtube_video_converter- EPSS Score: %13.24
- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3837
The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data during serialization and deserialization, which allows attackers to execute arbitrary code via an applica... Read more
Affected Products : android- EPSS Score: %0.79
- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025